Candlepinproject
1 CVEs tracked since 2013. Since Apr 2013, none of them reached CISA KEV.
Candlepinproject CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2013-04 | 1 | 0 |
Products
The products that kept showing up in Candlepinproject's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 4 most recently published vulnerabilities affecting Candlepinproject.
- CVE-2023-1832Improper authorization check in the server component6.8
- CVE-2021-4142The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authenticati...5.5
- CVE-2015-5187Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of excessive web traffic.6.5
- CVE-2012-6119Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.2.1
The record
- Peak rank
- #57 in Apr 2013
- Busiest month shown
- Apr 2013, 1 CVEs
- Months with a KEV entry
- 0 since Apr 2013
- Monthly snapshots
- 1 since 2013